Adobe has shipped emergency fixes for a maximum-severity flaw in Campaign Classic, its enterprise marketing automation platform, that allows arbitrary code execution without any user interaction.
The vulnerability, tracked as CVE-2026-48449, carries a perfect 10.0 CVSS score. Adobe describes it as incorrect authorization that could result in arbitrary code execution in the context of the current user, requiring no action from the victim.
The same patch round covers a second issue, CVE-2026-48448 (CVSS 8.6), a SQL injection weakness that could allow arbitrary file reads. Both are fixed in Campaign Classic v7.4.3 build 9398 on Windows and Linux.
Adobe said it is not aware of either vulnerability being exploited in the wild, but the severity and the zero-interaction requirement make patching urgent for the marketing teams that run the platform.
In a separate advisory, Adobe also addressed eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution. The batch includes CVE-2026-48390, CVE-2026-48391, CVE-2026-48395, and CVE-2026-48396, all rated 8.6, plus four other issues scored 7.8 or 8.2, including path traversal and out-of-bounds writes.
Security researcher Kieran, known as kaiksi, was credited with discovering five of the Bridge flaws, while researcher yjdfy reported the remaining three. Users are advised to apply the latest updates as soon as possible.

